Skip to content

Automate dependency updates with Dependabot #792

Description

@PhilipLeddin

Goal

Keep this pnpm monorepo and its GitHub Actions dependencies up to date automatically, while validating changes before they are merged.

Scope

  • Configure Dependabot version updates for the repository's pnpm workspace manifests and lockfiles, including the separately locked packages/uilib package.
  • Check for updates weekly, apply an explicit 3-day cooldown after a dependency release, and group compatible updates to keep pull-request volume manageable.
  • Configure weekly updates for GitHub Actions with the same 3-day version-update cooldown.
  • Enable the dependency graph, Dependabot alerts, and Dependabot security updates so known vulnerabilities are reported and secure-version pull requests are created. These repository security settings require a repository administrator; they cannot be enabled by dependabot.yml alone.
  • Ensure Dependabot pull requests run the repository's applicable build, test, and lint checks.

Merge policy

Dependabot should automatically open update pull requests; this does not mean those pull requests should be merged automatically. Keep auto-merge disabled initially. Consider enabling it later only for agreed low-risk updates after required checks and branch protection are verified; major updates should remain subject to review.

The 3-day cooldown applies to version updates only. Security update pull requests are not delayed by this cooldown.

Acceptance criteria

  • Dependabot configuration covers pnpm dependencies across the monorepo and GitHub Actions.
  • Version updates observe a 3-day cooldown; security updates remain unaffected.
  • A repository administrator enables the dependency graph, Dependabot alerts, and security update pull requests.
  • Dependabot pull requests receive the applicable CI checks.
  • The first generated updates are reviewed and the setup is verified; no update is auto-merged by default.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions